Quick 260927-q23 (CR-01), unit coverage that runs under -short.
- bouncer: TestRefreshAudienceForSubject covers active, pre/post cutoff,
missing, nil provider, non-numeric sub, provider error, and proves
token-only refusals never reach the provider
- bouncer: TestJWTGuardTokensValidAfter pins the unchanged "User not found"
message and errors.Is(err, ErrSubjectRejected)
- cabana: TestPhase10Coverage subtest pins cookie expiry on subject
refusals, no cookies over Bearer or on a provider error, and the
post-cutoff success path
Fixes review finding CR-01 (quick 260927-q23): POST {prefix}/api/v1/auth/refresh
minted a new token without loading the admin, so a session kept alive by the
SPA's refresh-on-401 survived admin:reset-password, deactivation and deletion.
This broke Phase 9 truth T-09-04.
- bouncer: extract the JWT guard's subject lookup into subjectPrincipal and
issuedBeforeCutoff (same order and messages), add ErrSubjectRejected
- bouncer: add RefreshAudienceFor, which runs the guard's subject checks
after the token-only checks and before minting; Refresh and
RefreshAudience are unchanged (nil hook)
- cabana: share one lazyBackendUsers provider between the backend guard and
refresh; a cookie refresh refused for its subject expires summer_admin
- test: TestAdminRefreshRevocation (Postgres, real admin:reset-password)
- 10-SECURITY-REVIEW.md: T-10-01..T-10-25 and T-10-SC with mitigation,
test or gate stage, observed result, residual risk and the removal
(mutation) checks behind every high threat
- 10-VALIDATION.md: executed task commands, gate statuses, Wave 0 done,
nyquist_compliant after scripts/check-phase10.sh --all passed
- --hygiene refuses localStorage, sessionStorage, indexedDB or document.cookie
outside admin/src/state/useSidebar.ts (T-10-22)
- --self-test plants each violation with a scratch test import, so the
refusal must come from that rule and not from the untested-module check
- scripts/check-phase10.sh with --self-test, --go, --security, --postgres,
--spa, --openapi, --dist, --hygiene, --evidence and --all
- phase10_detect refuses failed, skipped, zero-test, non-JSON and build-failed
go test runs and named tests that did not pass
- the two known fonoteka parity failures are the only allow-listed ones and
refuse the gate once they pass again
- hygiene enforces the framework/app boundary, SC-4 alias-only API types,
typed-client-only HTTP, no raw HTML, same-origin dist, named lucide imports,
no retired admin prefix routes and a test import for every SPA module
- 41 unit and component suites under admin/tests/{app,state,shell,list,form,relation,views,ui}
covering states and a11y roles; every src module is imported by a test
- typed fixture helper assigns each JSON fixture to its generated OpenAPI type
- fix: iconFor ignores inherited object members such as "constructor"
- fix: field controls import ./control instead of the registry (import cycle
left a renderer unregistered depending on module load order)
- fix: dropdown shows the placeholder for an unknown stored value next to an emptyOption
- fix: list announces a failed schema load even when the rows arrive after it
- tailwind no longer scans admin/tests; boardwalk/dist rebuilt
- useSidebar: collapsed below 1100px (matchMedia) or by the admin's choice,
persisted as a boolean under summer-admin.sidebar; the viewport never
overwrites the stored choice
- SectionPanel collapse and rail expand buttons; SectionFlyout (role menu)
opens on hover, focus, Enter or ArrowDown on a rail item, closes on Esc or
about 200 ms after leaving and returns focus to the rail item
- Breadcrumbs with plugin, controller and record crumbs; UserMenu (Reka
DropdownMenu) with initials, name, role and Wyloguj
- useAuth.logout POSTs /auth/logout, clears user, navigation and settings
and routes to login even when the call fails
- applyColorScheme toggles .dark from prefers-color-scheme (no toggle, A6)
- newest toast first, 200 ms fade and scale for dialogs and toasts
- one relation-manager type constant in the registry
- shell smoke tests; tests default to a desktop, light matchMedia
- relation-manager registered in the field registry; renders only on an
existing record, never on create, and is never part of the save body
- RelationManager: relation schema label and comment, debounced search,
selectable linked list (DataTable relation variant), toolbar buttons in
declared order, confirmed unlink with plural messages and toasts
- RelationPickerModal: Reka Dialog (aria-modal, focus trap, Esc) over the
candidates endpoint five per page, selection kept across pages, Dodaj (N)
POSTs link, focus returns to the opener
- admin OpenAPI documents search, sort, dir, page and per_page on the linked
and candidate relation routes so the SPA sends them typed
- neutral acme.demo.widgets members fixtures and relation smoke tests
- FormTabs groups fields by tab (untabbed fields in the default tab) as a
segmented tablist; a tab holding invalid fields after a 422 shows a
count badge and the form switches to the first invalid field
- switch, checkbox and relation join the renderer registry: toggle cards
(role=switch, 20px checkbox) keep a numeric value numeric; relation
fields are read-only labels from meta.labels, a searchable single
select over fields/{field}/options with emptyOption first, or ordered
removable chips with an appending search (300 ms debounce, 20 per
page, more on scroll or the more action)
- FormView gets the back button, record title and update subtitle, a
sticky footer (Usuń with deleteConfirm then DELETE, Anuluj, Zapisz i
zamknij to the mapped redirectClose, Zapisz), and asks before leaving a
dirty form on any route change plus a beforeunload guard
- Settings: the rail pins Ustawienia to the bottom when /settings is
non-empty; /settings lists pages by category; /settings/:code renders
the settings schema through FormGrid and the registry, PUTs the values
and maps a 422 like the record form
- New backend::lang keys (form.more_options, tab_default, discard,
settings.back); form and settings smoke tests; boardwalk/dist rebuilt
- List state (search, sort, dir, page, per_page, filter[<name>]) lives in
the URL query through parseListQuery/toListQuery; every change is a
router replace and clears the selection; search is debounced 300 ms and
resets the page
- DataTable renders the schema columns with a tri-state page checkbox,
asc/desc/none sorting with aria-sort, selected rows, a sticky header,
eight skeleton rows while loading and an empty slot
- CellValue renders text (muted dash when empty, arrays comma-joined),
datetime as YYYY-MM-DD HH:mm and switch as the Tak/Nie pills
- The heading shows the plural recordCount and the create button;
delete sits in the toolbar, disabled without a selection, and confirms
with the plural deleteConfirm in a Reka alert dialog before POSTing
bulk-delete; a 409 shows a danger toast
- FilterBar renders switch (JSON of the option value), daterange
(from..to) and scope filters (choices from filters/{scope}/options)
- Pagination shows the range, the per-page select over perPageOptions
(hidden with one choice) and a pager with ellipsis
- The tracer smoke test skips the new checkbox column; new backend::lang
list keys; boardwalk/dist rebuilt
- The SPA loads the backend::lang bundle before /auth/me, sets the
document language from meta.locale and renders plural messages with
Intl.PluralRules; interpolate mirrors phrasebook for :name/:Name/:NAME
- Create and record routes; mapWinterUrl maps recordUrl and redirects
onto the controller's list, create and record routes only
- List rows open their record; FormView loads the form schema and the
record, shows context-allowed fields in the span grid, saves values
keyed by field name and toasts the resolved saved message
- A 422 puts each message under its field (aria-invalid,
aria-describedby), shows the plural banner, focuses the first invalid
field in schema order and clears a field's error on change
- The D-05 registry maps text, textarea, number and dropdown; any other
type renders the unsupported-field box with the type in DM Mono
- The admin OpenAPI document declares the write request bodies
(AdminRecord, AdminIDsRequest) and the list filter query as a
deepObject, so the typed client can send them
- New backend::lang form.load_failed key; boardwalk/dist rebuilt
- pact.FilterOptions on the model serves a scope filter's choices; a scope
filter whose model lacks it fails activation (D-27)
- GET /{vendor}/{plugin}/{controller}/filters/{scope}/options answers a
declared scope filter behind the controller permission with localized
{value, label} choices, 404 otherwise
- Every admin route documents a typed success schema, and protected routes
document 401, 403 and 404 (422 on writes); SuccessEnvelope is gone and
logout writes a typed AdminLogoutData
- jsonScalar and fieldContext decode their served shapes
- TestPhase10OpenAPIConformance calls every inventoried route through the
assembled router on PostgreSQL and decodes each body into its documented
type with unknown fields disallowed, checking admin.json's schema ref
- The SPA aliases every new schema type; Tailwind no longer scans the
generated API files, so API changes do not churn boardwalk/dist
- phrasebook ships the backend::lang admin strings (pl, en) with CLDR
plural maps, loads them as namespace backend, applies
pact.HasLangOverrides trees (lang/<locale>/<namespace>/<group>.yaml)
after every namespace, and fails activation when a backend key cannot
convert to plural forms
- Translator.Forms, Bundle, Resolved and Has serve keys as CLDR form maps
- Public GET /lang returns every backend::lang key for the request
locale over the fallback locale, Cache-Control no-cache
- config_list, config_form and config_relation accept a strict messages
block; omitted keys take framework defaults, schemas serve every message
as CLDR forms, and activation fails on a missing phrase key
- toolbar.buttons is an ordered [create, delete] list; the Winter string
form, duplicates, unknown actions and delete without showCheckboxes fail
at boot, and create is dropped when the controller has no form
- Form schema serves the raw Winter redirects; scaffold emits the list
syntax; form and relation schema routes are typed in the admin OpenAPI
- FieldRelationContract/FieldRelationProvider bind every type: relation
field to a belongsTo foreign key or a belongsToMany pivot; activation
fails naming plugin, controller and field on a missing or broken contract
- GET /{vendor}/{plugin}/{controller}/fields/{field}/options serves
{value, label} pages scoped by pact.RelationExtendOptionsQuery, behind
the controller permission; read-only and non-relation fields are 404
- Saves apply present relation keys after the Before hook: ids are
revalidated through the same scoped query (422 and full rollback
otherwise), belongsTo sets the foreign key, belongsToMany replaces pivot
rows in submitted order with the order column set to the index
- Show, create and update return relation values in data and meta.labels
- A belongsTo on a protected fill key is read-only (D-26)
- One six-segment GET pattern dispatches relation lists and field options,
which ServeMux cannot register side by side
- Admin OpenAPI documents the options route and RecordEnvelope